You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用ArgoCD Image Updater访问GCR报错:无法读取镜像标签

ArgoCD Image Updater访问GCR权限拒绝问题排查

报错日志

time="2022-09-13T15:40:02Z" level=debug msg="Using version constraint '^0.1' when looking for a new tag" alias= application=ms-echoserver-imageupdate-test image_name=test-build/argo-imageupdater-test image_tag=0.9 registry=gcr.io
time="2022-09-13T15:40:02Z" level=error msg="Could not get tags from registry: denied: Failed to read tags for host 'gcr.io', repository '/v2/test-build/argo-imageupdater-test/tags/list'" alias= application=ms-echoserver-imageupdate-test image_name=test-build/argo-imageupdater-test image_tag=0.9 registry=gcr.io
time="2022-09-13T15:40:02Z" level=info msg="Processing results: applications=1 images_considered=1 images_skipped=0 images_updated=0 errors=1"

当前配置

apiVersion: v1
kind: ConfigMap
metadata:
  name: argocd-image-updater-config
  labels:
    app.kubernetes.io/name: argocd-image-updater-config
    app.kubernetes.io/part-of: argocd-imageupdater

data:
  log.level: debug
  registries.conf: |
    registries:
    - name: Google Container Registry
      api_url: https://gcr.io
      ping: no
      prefix: gcr.io
      credentials: pullsecret:argocd/gcr-imageupdater
      #credentials: secret:argocd/sundayy#creds

排查与解决建议

  • 检查Pull Secret的格式与位置
    确保argocd/gcr-imageupdater Secret存在于argocd命名空间,类型为kubernetes.io/dockerconfigjson。Docker配置需包含gcr.io的认证条目,格式示例:

    {
      "auths": {
        "gcr.io": {
          "auth": "<base64编码的'_json_key:<服务账号JSON内容>'>"
        }
      }
    }
    

    可通过命令验证内容:kubectl get secret gcr-imageupdater -n argocd -o jsonpath='{.data.\.dockerconfigjson}' | base64 -d

  • 切换为服务账号JSON密钥凭证
    注释当前pullsecret配置,启用secret:argocd/sundayy#creds配置。确保该Secret的creds键值为完整GCP服务账号JSON内容,且账号具备Artifact Registry Reader或Storage Object Viewer权限(GCR依赖GCS存储,需对应权限读取镜像标签)。

  • 验证服务账号权限
    即使标注拥有所有者权限,仍需确认账号是否具备artifactregistry.repositories.listTags(适用于迁移后的Artifact Registry)或storage.objects.list(适用于传统GCR存储桶)权限,可通过GCP IAM控制台检查绑定关系。

  • 确认Registry API地址
    GCR的V2 API地址为https://gcr.io,当前配置无需调整。

内容的提问来源于stack exchange,提问作者gaurav agnihotri

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.19 20:55:20